nug

Build log

host

nug 0.4.0 · fail · run nug-0.4.0-1791021632440
118 of 118 lines
1Resolving Hex dependencies...2Resolution completed in 0.199s3Unchanged:4  circular_buffer 1.1.05  cowboy 2.6.3 VULNERABLE!6    EEF-CVE-2026-8466 (HIGH)7    aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x88    Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy9    https://osv.dev/vulnerability/EEF-CVE-2026-84661011    EEF-CVE-2026-65624 (MEDIUM)12    aka: CVE-2026-6562413    Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion14    https://osv.dev/vulnerability/EEF-CVE-2026-656241516    GHSA-w4f7-4cxr-rv3c (MEDIUM)17    aka: CVE-2026-43966, EEF-CVE-2026-4396618    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability19    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c20  cowlib 2.7.3 VULNERABLE!21    EEF-CVE-2026-59248 (HIGH)22    aka: CVE-2026-5924823    Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS24    https://osv.dev/vulnerability/EEF-CVE-2026-592482526    EEF-CVE-2026-43970 (HIGH)27    aka: CVE-2026-43970, GHSA-84f2-rp86-235p28    Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame29    https://osv.dev/vulnerability/EEF-CVE-2026-439703031    EEF-CVE-2026-43968 (MEDIUM)32    aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r33    CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/134    https://osv.dev/vulnerability/EEF-CVE-2026-439683536    EEF-CVE-2026-7790 (HIGH)37    aka: CVE-2026-7790, GHSA-32p9-57cr-4x6538    Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS39    https://osv.dev/vulnerability/EEF-CVE-2026-779040  elixir_make 0.10.041  gun 1.3.3 VULNERABLE!42    EEF-CVE-2026-43973 (HIGH)43    aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7744    gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion45    https://osv.dev/vulnerability/EEF-CVE-2026-439734647    GHSA-w4f7-4cxr-rv3c (MEDIUM)48    aka: CVE-2026-43966, EEF-CVE-2026-4396649    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability50    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c51  idna 6.1.152  interactive_cmd 0.1.453  jason 1.4.554  mime 2.0.755  nerves 2.0.0-pre.256  nerves_discovery 0.1.557  nerves_logging 0.2.458  nerves_runtime 0.13.1359  nerves_system_bbb 2.30.260  nerves_system_br 1.34.461  nerves_system_mangopi_mq_pro 0.17.262  nerves_system_qemu_aarch64 0.4.263  nerves_system_rpi0 2.1.264  nerves_system_rpi4 2.1.265  nerves_system_rpi5 2.1.266  nerves_system_trellis 0.5.067  nerves_system_x86_64 1.34.268  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.169  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.170  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.171  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.172  nerves_toolchain_x86_64_nerves_linux_musl 15.3.173  nerves_uevent 0.1.774  nug 0.4.075  plug 1.20.376  plug_cowboy 2.1.3 VULNERABLE!77    EEF-CVE-2026-32688 (HIGH)78    aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg279    Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy80    https://osv.dev/vulnerability/EEF-CVE-2026-3268881  plug_crypto 2.2.082  property_table 0.3.483  ranch 1.7.184  ring_logger 0.11.785  tablet 0.3.386  telemetry 1.4.287  tesla 1.21.388  toolshed 0.5.089  uboot_env 1.0.290  unicode_util_compat 0.7.191Found packages with security advisories, see above for details92All dependencies have been fetched93===> Analyzing applications...94===> Compiling ranch95     ┌─ src/ranch_ssl.erl:96     │97 142 │  	case ssl:ssl_accept(CSocket, Opts, Timeout) of98     │  	     ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead99100101    ┌─ src/ranch_conns_sup.erl:102    │103 80 │  	catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},104    │  	╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.105Compile directive 'nowarn_deprecated_catch' can be used to suppress106warnings in selected modules.107108109===> Analyzing applications...110===> Compiling cowlib111===> Compiling src/cow_sse.erl failed112    ┌─ src/cow_sse.erl:113    │114 56 │  	-> {event, parsed_event(), State} | {more, State}.115    │  	                           ╰── type variable 'State' is only used once (is unbound)116117118** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"